TL;DR
CISA disclosed eight vulnerabilities in the Mira Hormone Monitor and its Android app. The worst, CVE-2026-68067, scores a critical CVSS 9.8. It lets a remote attacker control user accounts by bypassing the cloud login entirely. No public exploitation has been confirmed.
- Total: 8 CVEs
- Severity: 2 Critical · 3 High · 3 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-68067
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-68067 | 9.8 | Mira Hormone Monitor, Mira Android App Weak Authentication | — | Not exploited |
| CVE-2026-67568 | 9.1 | Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials | — | Not exploited |
| CVE-2026-66875 | 8.8 | Mira Hormone Monitor, Mira Android App Missing authentication for critical function | 01.07.01.53, 4.5.18 | Not exploited |
| CVE-2026-67558 | 7.4 | Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing | — | Not exploited |
| CVE-2026-66098 | 6.5 | Mira Hormone Monitor, Mira Android App Missing authentication for critical function | — | Not exploited |
| CVE-2026-66832 | 6.5 | Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings | 01.07.01.53, 4.5.18 | Not exploited |
| CVE-2026-66340 | 5.3 | Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts | — | Not exploited |
| CVE-2026-64934 | 4.3 | Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision | — | Not exploited |
Why it matters
The Mira monitor tracks hormone levels for fertility planning. So its data is deeply personal. An attacker who can control user accounts gains access to that sensitive health record.
The impact goes beyond privacy. Researchers warn that tampered data could cause missed fertility windows or failed treatments. Therefore, the safety stakes are real, not just theoretical.
How the attack works
The most severe bug sits in the Mira cloud API. According to the advisory, the login endpoint accepts any format-valid password. It then returns a live session token for the matching email address.
As a result, an attacker needs only a target’s email to hijack the account. This single flaw earns its critical CVSS score. Other bugs involve weak Bluetooth pairing that lets nearby attackers rebind the device.
Account takeover in focus
CVE-2026-68067 turns a routine login into an open door. With a valid token, an attacker reads hormone records and changes account settings. That ability to control user accounts is the headline risk here.
Affected versions
The flaws affect Mira Monitor Firmware 1.7.1.47 and Mira Android App 4.5.15.4. Researchers at Northeastern University’s SPQR Lab reported the issues. You can read the full CISA advisory ICSMA-26-223-01 for the complete CVE list.
Exploitation status
No known public exploitation has been reported to CISA. Likewise, no proof-of-concept has been published. The vendor, Quanovate, completed two rounds of fixes before disclosure.
Patch and mitigation steps
Update the Mira app and device firmware as fixes roll out. Then review your account for any unfamiliar activity. CISA also advises limiting device exposure and following its social-engineering guidance.
Beyond patching, keep the monitor out of untrusted Bluetooth range. Strong, unique account credentials add another layer of defense.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.